CISA, NSA, FBI Release Advisory Warning of BlackTech, PRC-Linked Cyber Activity
cisa.gov
cisa.gov
I wonder how best to handle this kind of downgrade attack. Is reverting to an older firmware version an intended, supported feature? If so, I assume it's present in case the customer has a problem with the latest firmware and they want to revert. Maybe it makes sense to implement some restrictions on reversions -- e.g. they can only be done with physical access to the device, and it becomes impossible after an upgrade has been in place for 1 month say.
The focus on international subsidiaries was very interesting to me. I wonder what, specifically, it is about a subsidiary that makes it a softer target. Perhaps it's easier to gain physical access to a subsidiary office.
I think its more common on recent routers as well.
Here’s another one with recent updates from the chief architect of metasploit. https://www.rapid7.com/blog/post/2013/07/02/a-penetration-te...
The most popular router brand is TP-Link which is a Chinese Brand. Both Eero and Nest from Amazon to Google aren't available worldwide. Netgear and Linksys has poor Firmware update frequency. That is pretty much left with ASUS which I have a decade old unfix bug with my ISP that randomly fails to get new IP.
I only wish Apple would come back with new AirPort Extreme.
Docker can also be used. Don't get the SE or other cheaper versions, they use ARM chips. Gold/Gold Plus use x86.
[1] https://firewalla.com/products/firewalla-gold [2] https://firewalla.com/products/firewalla-gold-plus
If someone told you a cup may contain poison, would your first reaction be to drink it just to be sure?
https://arstechnica.com/tech-policy/2014/05/photos-of-an-nsa...
Your example of highly-targeted physical interception by state-level actors is irrelevant here.
Essentially, this means that there is zero risk, unless you are a target, at which point any unintentional hardware bug caused by the aforementioned corner-cutting will become a concern.
[0] https://linux-sunxi.org/Linux_mainlining_effort
btw, I asked about this 5 months ago [0] and got some interesting replies. I ended up purchasing a PCEngines board (just before they went out of business)
This bug has existed for over a year, with no fix in sight.
Unifi's quality is dropping day by day. I'm convinced they don't use their own networking tools.
The same Apple that refuses to publish official EOL support dates?
OpenWrt is generally more trustworthy than the stock firmware, but I wouldn't expect any of these solutions to keep out a state actor, nor even a script kiddie with a lot of time on their hands. Trust level is more like not having a known stock firmware botnet motel, and maybe keeping some cruddy US IoT products on their own VLAN.
pfSense box + Ruckus WAP
I went with a Netgate SG-1100 and am happy with it for 200/100 WAN. I have a Ruckus R610 (used on ebay for $100) that gets regular Unleashed firmware updates and is far and away the best WAP I have ever owned.
The only one I've ever had fail is a 7 year old G3 Flex indoors.
I chucked up hostapd on Debian at one point and was surprised to see how good coverage it got. Outperformed devices in higher price-range without even attaching an antenna.
They don't seem to hesitate to use demonyms -- they do use 'Japanese' for example (https://www.cisa.gov/news-events/alerts/2023/09/27/nsa-fbi-c...).
I think that is the lingua franca used when referring to China.
2. Re being more careful with negative statements -- they are clearly unable to do so consistently, see below:
[1] Look at the very clear headlines featuring "Iranian Government-Sponsored APT Actors" in https://www.cisa.gov/news-events/cybersecurity-advisories/aa... and "Iranian State Actor" in https://www.cisa.gov/news-events/cybersecurity-advisories/aa...
[2] Again, look at the very clear headlines featuring "Russian State-Sponsored" in https://www.cisa.gov/news-events/cybersecurity-advisories/aa...
Why are they not equally 'careful' here? Why are they not using the country's "official" names such as IRI (Islamic Republic of Iran) or RF (Russian Federation)?
Note that I'm not even going into the rabbit hole of "PRC-Linked" vs "Iranian Government-Sponsored" -- although that is perfectly worth questioning also, because if you go into the actual article on Iran, they weasel out by saying "likely Iranian government-sponsored APT", whereas here it's only "PRC-linked" because we do not know for sure.
https://en.wikipedia.org/wiki/Taiwan
> Republic of China
https://en.wikipedia.org/wiki/China
> People's Republic of China
From what I've read western agencies helped Ukraine and the cyber efforts were mostly neutered.
It's one thing to be a random org in peace time but in war the deep penetration into Chinese networks will have exposed plenty of Chinese efforts not yet disrupted and all that was super secret and careful before turns into open warfare.
So it's not like the west is going in blind. The US spends mountains on this stuff, not including the mass of western commercial infosec companies tracking these critical "threat groups" as their business model. NSA is huge as it is and who knows how many federal and DOD agencies have cyber mandates these days.
All systems are inherently vulnerable but some mass back doors in routers has been speculated to death by people way smarter than me and most I've read is that the risk is largely over stated to the civilian population. The router doomsday scenarios are always super hand wavvy in the details.
https://www.forbes.com/sites/davidhambling/2023/05/22/ukrain...
This is what $500 delivers in the field https://twitter.com/UAWeapons/status/1706705383220191290 ~$3mil T-72B3 obr. 2022 going in smoke https://gagadget.com/en/osint/324992-a-500-fpv-drone-destroy...
Few days earlier 2S9 Nona-S https://twitter.com/UAWeapons/status/1705852827233300773 ~$1mil
If you really want to get outraged by something read about russians behind Lancet suicide drones https://www.sensusq.com/blog/sensusq-analysis-on-the-zala-42... Son of the de facto owner/ceo of the company currently works at UN Institute for Disarmament Research (UNIDIR) in Geneva.
I don’t see Russia running out of tanks.
There’s evidence they are running out of tanks, like activating T62’s and using Indias T90S’s.
They aren’t out of tanks altogether but they are clearly going through tanks faster then they can make them.
Currently there are 2500 tank and >4000 armored carrier losses documented on video/pictures https://www.oryxspioenkop.com/2022/02/attack-on-europe-docum... while UA claims double that in the field https://index.minfin.com.ua/en/russian-invading/casualties/
~10 tank loses a day while ru barely makes under 10 new tanks and refurbishes tens per month now. https://en.defence-ua.com/industries/how_many_tanks_a_month_...
Re: Ukraine claims - is that the one where they claimed to have destroyed 4,700 tanks out of 3,500?
MediaZona, an organization run by strongly anti-Putin, pro-Ukraine owners in partnership with the BBC, is going to be the most accurate casualty information you can actually get: https://en.zona.media/article/2022/05/11/casualties_eng
And please, enlighten me: how exactly are they taking that many tank losses when they’re literally dug in, not moving, and have pulled the tanks back? They don’t even have to fight, the Ukrainians are doing a fine job tripping every land mine in the region by themselves.
Oryx literally counts visually documented losses on both sides it’s likely to be a lower bound with rather large confidence on both sides of the conflict.
But it’s still a lower bound.
How is that “proven to be false”.
> MediaZona, an organization run by strongly anti-Putin, pro-Ukraine owners in partnership with the BBC, is going to be the most accurate casualty information you can actually get: https://en.zona.media/article/2022/05/11/casualties_eng
But those numbers are very different to the pentagon documents, so they must be false right?.
> And please, enlighten me: how exactly are they taking that many tank losses when they’re literally dug in, not moving, and have pulled the tanks back? They don’t even have to fight, the Ukrainians are doing a fine job tripping every land mine in the region by themselves.
Because Russia isn’t dug in and not moving they are constantly trying to counter attack.
Not only that dug in tanks and tanks behind the front line are still vulnerable to drone borne weapons which are very popular in this war.
The difference is that we’re fighting a proxy war with Russia over Ukraine. With Taiwan, it will be a direct war due to the security guarantees we have given Taiwan.
I don't think their goal has ever been sabotage as much as it has been intelligence gathering, but I suspect a lot of their efforts have gone underreported.
Russia did successfully brick thousands of consumer satellite modems to disrupt communications in the opening hours of the Ukraine campaign. Everybody reported on Elon Musk swooping in and playing savior, but they acted like he's the first person to bring satellite service to Ukraine and neglected to mention incumbent ISPs' devices operating in the area had been destroyed in targeted cyberattacks (later, Russia went low-tech and just started lobbing artillery at ground stations).
Because of this oversight, nobody really understood why he pulled the service from the front lines-- he saw what Russia was capable of and didn't want Starlink to become a military target itself.
I know Cisco is also the biggest target and it's obvious that consumer routers are less secure, but at this point the amount of backdoors in Cisco routers raises the question if there is another player that has better security.
Honest question: Is it just selective awareness or are Cisco routers not the best option when it comes to security (for higher profile targets)?
edit: replace "a bad" with "not the best"
A few weeks ago it was all about Unifi (and many others) being backdoored due to some upstream supplier being pwned by the NSA.
So it's not only Cisco. It's all of them.
https://www.theregister.com/2023/09/19/marvell_disputes_clai...
Pepperidge farm remembers when Cisco's fix to a remote code execution CVE on routers was to check for the default `curl` user agent
https://web.archive.org/web/20201207153246/https://twitter.c...
Cisco did do a good job burying that in search results though, got to give them props, if it isn't stealing material from blackhat presenters by force physically, it's buying PR.
Each of the previously mentioned groups have their own implementation and licenses for specific IOS version running inside the network device (whether a Firewall, Router, Switch, or Switch with routing capabilities...etc). It has been long known that Cisco's poor software is due to the hundreds of modules/features they try to support on these devices (you never know which device will receive updates and for how long).
System administrators/Network Engineers alike always complain about the poor quality of Cisco's Software[1][2]
[1] https://www.reddit.com/r/sysadmin/comments/cpcxjx/has_cisco_...
[2] https://www.reddit.com/r/networking/comments/137csr0/why_the...
If someone told me a missile was going to hit my apartment I probably wouldn't believe them, but I might go grab coffee
Really! You can believe me! Unlike the NSA, I have no history of lying to you!
Hope there's a 24-hour Starbucks close by (but not too close).
Now maybe I'm with the NSA and I know where you'll be. Maybe I'm just an informant and I know where the NSA thinks you'll be.
What will you do?
If I administered commercial routers, the request would seem reasonable to me.
Either way, let's wait for the video, I don't believe Paul that the Brits are here.
> 3 Letter Agencies
Pick one.
They have no incentive to lie here.
But see this for what it is: An attempt at gaining trust so more people will voluntarily work with them and give them data.
You could argue if they lied the incentive wouldn't be worth the risk, but proving they lied about this would be difficult and that's a seperate argument from the one you made.
And they're not likely to give sources because of the whole "protecting sources and methods" bias they have to not reveal how they know what they know.
I'm making an argument about their motive here. The damage they'd face from lying is great (what if another leak comes out? What if a backdoor is found in the patch communicating with NSA infrastructure?) and the possible benefit relatively small.
How are they supposed to take damage from lying? They have no credibility to lose. The NSA Wikipedia page takes a while to scroll through and is a saga of backdoors and skullduggery. "Spies lied, news at 11" will read the headline. I'm not saying this specific thing is true or not, what do I know. But if it turned out to be a lie, who could claim to be surprised? It has entered the public record that they developed tech to pretend to be foreigners like the PRC when conducting their cybercrime activities.
Could be fine. Could be beneficial for Amazon's cryptographic security. But I know I'd be worried on what her reaction would be if the NSA came to her privately and asked for her to make a change at AWS that makes it easier for the NSA to exploit.
As for them lying....you have to look at incentives. Spies lie for a reason. They twist words, they lie by omission, they attack peoples' character, they claim their push for changes in the name of public safety is more important than freedoms.
They don't lie just for the sake of lying. Lying is not its own reward.
From wikipedia. Major compromise tbh :unamused:
[13] Thomas R. Johnson (2009-12-18). "American Cryptology during the Cold War, 1945-1989.Book III: Retrenchment and Reform, 1972-1980, page 232" (PDF). National Security Agency. Archived (PDF) from the original on 2015-04-25. Retrieved 2015-07-16 – via National Security Archive FOIA request. This version is differently redacted than the version on the NSA website.
[14] Thomas R. Johnson (2009-12-18). "American Cryptology during the Cold War, 1945-1989.Book III: Retrenchment and Reform, 1972-1980, page 232" (PDF). National Security Agency. Archived (PDF) from the original on 2015-04-25. Retrieved 2015-07-16 – via National Security Archive FOIA request. This version is differently redacted than the version on the NSA website.
https://www.cisa.gov/news-events/cybersecurity-advisories/aa...
https://attack.mitre.org/versions/v13/techniques/T1021/004/
> G0098 BlackTech BlackTech has used Putty for remote access.[2]
https://symantec-enterprise-blogs.security.com/blogs/threat-...
> The Threat Hunter Team at Symantec, a division of Broadcom (NASDAQ: AVGO), has uncovered a new espionage campaign carried out by the Palmerworm group (aka BlackTech) involving a brand new suite of custom malware, targeting organizations in Japan, Taiwan, the U.S., and China.